Vulnerabilities (CVE)

Filtered by vendor Moodle Subscribe
Total 525 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2004-1711 1 Moodle 1 Moodle 2023-12-10 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in post.php in Moodle before 1.3 allows remote attackers to inject arbitrary web script or HTML via the reply parameter.
CVE-2004-1978 1 Moodle 1 Moodle 2023-12-10 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in help.php in Moodle before 1.3 allows remote attackers to inject arbitrary HTML and web script via the text parameter.
CVE-2004-1425 1 Moodle 1 Moodle 2023-12-10 5.0 MEDIUM N/A
Directory traversal vulnerability in file.php in Moodle 1.4.2 and earlier allows remote attackers to read arbitrary session files for known session IDs via a .. (dot dot) in the file parameter.
CVE-2004-2232 1 Moodle 1 Moodle 2023-12-10 7.5 HIGH N/A
SQL injection vulnerability in sql.php in the Glossary module in Moodle 1.4.1 and earlier allows remote attackers to modify SQL statements.
CVE-2004-2234 1 Moodle 1 Moodle 2023-12-10 7.5 HIGH N/A
Unknown vulnerability in Moodle before 1.2 allows teachers to log in as administrators.